cve/2023/CVE-2023-4104.md
2024-06-18 02:51:15 +02:00

1014 B

CVE-2023-4104

Description

An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN setups.This bug only affects Mozilla VPN on Linux. Other operating systems are unaffected. This vulnerability affects Mozilla VPN client for Linux < v2.16.1.

POC

Reference

Github